
Disable Admin Notices – Hide Dashboard Notifications Security & Risk Analysis
wordpress.org/plugins/disable-admin-noticesDisable admin notices and hide dashboard notifications from plugins, themes and core. Hide all notices, selected ones, or show them in a single line.
Is Disable Admin Notices – Hide Dashboard Notifications Safe to Use in 2026?
Generally Safe
Score 98/100Disable Admin Notices – Hide Dashboard Notifications has a strong security track record. Known vulnerabilities have been patched promptly.
The 'disable-admin-notices' plugin v1.4.3 exhibits a mixed security posture. While the static analysis reveals a relatively small attack surface with all identified entry points (AJAX handlers) protected by authentication checks, and no dangerous functions or file operations, there are significant concerns regarding data handling. The complete lack of prepared statements for SQL queries is a major red flag, potentially exposing the site to SQL injection vulnerabilities. Furthermore, the relatively low percentage of properly escaped output suggests a risk of cross-site scripting (XSS) vulnerabilities.
The vulnerability history indicates a past pattern of medium severity vulnerabilities, primarily Cross-Site Request Forgery (CSRF). Although there are currently no unpatched CVEs, the historical trend of medium severity issues, coupled with the code analysis findings of raw SQL and insufficient output escaping, suggests a potential for future vulnerabilities if these issues are not addressed. The plugin does demonstrate good practices in its use of nonces and capability checks, and the absence of external HTTP requests and bundled libraries is a positive. However, the data handling deficiencies in the code and the historical vulnerability pattern warrant careful consideration.
Key Concerns
- SQL queries do not use prepared statements
- Only 59% of output is properly escaped
- 2 medium severity CVEs in history
Disable Admin Notices – Hide Dashboard Notifications Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Disable Admin Notices – Hide Dashboard Notifications <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update
Disable Admin Notices individually <= 1.4.0 - Cross-Site Request Forgery
Disable Admin Notices – Hide Dashboard Notifications Code Analysis
SQL Query Safety
Output Escaping
Disable Admin Notices – Hide Dashboard Notifications Attack Surface
AJAX Handlers 3
WordPress Hooks 26
Maintenance & Trust
Disable Admin Notices – Hide Dashboard Notifications Maintenance & Trust
Maintenance Signals
Community Trust
Disable Admin Notices – Hide Dashboard Notifications Alternatives
Hide Admin Notices
hide-admin-notices
Hide – or show – WordPress Dashboard Notices, Messages, Update Nags etc. ... for everything!
Hide Dashboard Notifications
wp-hide-backed-notices
Warnings and notices can be helpful for developers as they notify them for debugging issues with their code. Though these notices can be sometimes inf …
Disable Admin Dashboard Notices – Get a distraction free WordPress backend
disable-admin-dashboard-notices
"Disable Admin Dashboard Notices" is a handy WordPress plugin designed to streamline and enhance the user experience for WordPress website a …
Admin Notices Manager
admin-notices-manager
Better manage admin notices & never miss important developer messages!
Remove Admin Notices
remove-admin-notices
With this plugin you can remove all admin notices.
Disable Admin Notices – Hide Dashboard Notifications Developer Profile
37 plugins · 2.2M total installs
How We Detect Disable Admin Notices – Hide Dashboard Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/disable-admin-notices/admin/assets/css/general.css/wp-content/plugins/disable-admin-notices/admin/assets/js/notice.js/wp-content/plugins/disable-admin-notices/admin/assets/js/notice.jswbcr-notification-hide-styleHTML / DOM Fingerprints
wbcr-notice-hide-itemwbcr-notice-hide-titlewbcr-notice-hide-descriptiondata-notice-idwbcr_admin_noticewbcr_admin_notice_control